Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-47712

8.3 · HIGH
Published Oct 21, 2024 linux CWE-476 EPSS 0.36% (30th pctl)

Overview

CVE-2024-47712 is a high-severity vulnerability affecting linux linux_kernel. It was published on October 21, 2024 and has a CVSS 3.1 base score of 8.3 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.3, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param

In the `wilc_parse_join_bss_param` function, the TSF field of the `ies`

structure is accessed after the RCU read-side critical section is

unlocked. According to RCU usage rules, this is illegal. Reusing this

pointer can lead to unpredictable behavior, including accessing memory

that has been updated or causing use-after-free issues.

This possible bug was identified using a static analysis tool developed

by myself, specifically designed to detect RCU-related issues.

To address this, the TSF value is now stored in a local variable

`ies_tsf` before the RCU lock is released. The `param->tsf_lo` field is

then assigned using this local variable, ensuring that the TSF value is

safely accessed.

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.4.273, < 5.5 Affected

Frequently Asked Questions

What is CVE-2024-47712?

CVE-2024-47712 is a high-severity vulnerability affecting linux linux_kernel. It was published on October 21, 2024 and has a CVSS 3.1 base score of 8.3 (HIGH).

How severe is CVE-2024-47712?

This vulnerability has a CVSS 3.1 base score of 8.3, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-47712?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-47712?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-47712 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.